LAW OF THE REPUBLIC OF ARMENIA ON CYBERSECURITY

Գլխավոր տեղեկություն
Համար
HO-442-N
Տիպ
Law
Ակտի տիպ
Հիմնական ակտ (04.01.2026-մինչ օրս)
Կարգավիճակ
Active
Սկզբնաղբյուր
Published on a joint site 17.07.2026
Ընդունող մարմին
National Assembly
Ընդունման ամսաթիվ
04.12.2025
Ստորագրող մարմին
President of the Republic of Armenia
Ստորագրման ամսաթիվ
24.12.2025
Ուժի մեջ մտնելու ամսաթիվ
04.01.2026

LAW

 

OF THE REPUBLIC OF ARMENIA

 

Adopted on 4 December 2025

 

ON CYBERSECURITY

 

CHAPTER 1

 

GENERAL PROVISIONS

 

The purpose of this Law is to ensure cybersecure environment in information systems and critical information infrastructures operating in vital sectors of the Republic of Armenia.

 

Article 1.

Subject matter and scope of the Law

1. This Law shall regulate relations pertaining to ensuring the cybersecurity of information systems or critical information infrastructures operating in vital sectors, in particular, within the meaning of this Law, the scope of service providing entities, vital sectors, detection, notification, prevention and resolution of cyber incidents, the state administration system bodies in the field of cybersecurity and the scope of powers thereof, monitoring the compliance with the requirements of this Law, supervision, liability, cybersecurity audit, as well as other relations pertaining to cybersecurity.

2. Any other legal entity or individual entrepreneur not deemed a service provider within the meaning of this Law, may, under the procedure established by the Government, voluntarily assume or waive the obligations to ensure cybersecurity arising from this Law.

3. This Law shall extend to:

(1) legal entities and individual entrepreneurs simultaneously carrying out activities in one or more of the vital sectors listed in part 4 of Article 16 of this Law and operating an information system or critical information infrastructure;

(2) state and local self-government bodies.

4. This Law shall not extend to legal entities and individual entrepreneurs meeting the criteria for classification of micro- and small enterprises prescribed by the Law “On state support for small and medium-sized entrepreneurship”, except for cases when the specified entities operate a critical information infrastructure.

5. This Law shall not extend to compliance with cybersecurity requirements in respect of information systems operated by the authorised state bodies while performing their functions in the fields of defence, national security, foreign relations, and foreign intelligence activities.

6. This Law shall not extend to compliance with cybersecurity requirements relating to the operation of information systems and critical information infrastructures used to process information containing state secret.

7. This Law shall not extend to relations governing the field of cybercrimes regulated by other laws.

8. When implementing measures aimed at ensuring cybersecurity prescribed by this Law, the service provider shall, when performing any actions related to personal data, act in compliance with the requirements of the legislation regulating relations pertaining to processing of personal data.

9. When implementing measures aimed at ensuring cybersecurity prescribed by this Law, the service provider shall, when performing any actions related to information containing a state secret, as well as other secrets protected by law, act in compliance with the requirements of the legislation regulating relations pertaining to the secret protected by law, as well as the given secret.

 

Article 2.

Legislation on cybersecurity

1. Relations arising in the field of ensuring cybersecurity shall be regulated by the Constitution of the Republic of Armenia, this Law, the Law “On public information”, the Law “On the information systems regulatory body”, international treaties of the Republic of Armenia, and other legal acts.

2. Where the international treaties ratified by the Republic of Armenia prescribe norms other than those provided for by this Law, the norms of the international treaties shall apply.

 

Article 3.

Main definitions used in this Law

1. The following main definitions shall be used in this Law:

(1) cybersecurity — a set of organisational, technical and software means that protect the information processed, stored and transmitted in a computer, computer equipment, digital storage media, an information system, critical information infrastructure and electronic communication network against accidental loss, unauthorised access, use, disclosure, disruption, alteration, destruction, attack, copying, recording, dissemination and other unlawful intrusions or interference, while ensuring the availability, integrity, authenticity, confidentiality and accuracy of such information;

(2) authorised body — a state administration body developing and implementing policy in the sectors listed in point 16 of Annex to the Law “On the structure and activities of the Government” (hereinafter referred to as “the Authorised body”);

(3) autonomous body — the Information Systems Regulatory Commission provided for by the Law “On information systems regulatory body” (hereinafter referred to as “the Autonomous body”);

(4) information system security — the capability of an information system to withstand any situation that compromises the availability, authenticity, integrity, confidentiality and accuracy of data stored, processed, acquired or transmitted within such system or of services offered by that system or made available through that system;

(5) critical information infrastructure — automated control systems, information systems, equipment or parts thereof being operated in vital sectors, the disruption or destruction whereof may create threats to national security, defence, economy, social welfare, population health, environment, public order, international relations and governance continuity;

(6) vital sector — a sector of essential importance for the normal functioning of the population, economic activity, state security, public health and safety or environmental protection, and the protection of other vital interests of the Republic of Armenia;

(7) service provider — a legal entity or an individual entrepreneur specified in part 3 of Article 1 of this Law, legal entities or individual entrepreneurs meeting the criteria for the classification of micro- and small enterprises specified in part 4 of the same Article, that operate critical information infrastructure, as well as a state or local self-government body;

(8) digital infrastructure — within the meaning of this Law, an electronic trading platform, an online search engine, a cloud computing service, means for creating or verifying an electronic digital signature, services relating to the issuance of certificates for electronic digital signatures and other services associated with electronic digital signatures, an electronic communication service, a public electronic communication service, an Internet access service, a registry of the top-level national domain of Armenia;

(9) electronic trading platform — within the meaning of this law, a service that allows consumers and producers to conclude online electronic sales or service contracts through a website, electronic application or other similar means, in compliance with the requirements set forth in the Law “On trade and services” and the Law “On protection of consumer rights”;

(10) online search engine — a digital service that allows users to enter queries into websites or to search on websites only in certain languages using keywords, voice request, phrase, or other form of entry, and presents the results in any format where information related to the requested content may be found;

(11) cloud computing service — a digital service that, through the shared use of server and networked infrastructures, provides remote (online) access to data, software and other computing resources and enables the use of shared and scalable technical resources (including infrastructure, platforms and software) without the need for significant upfront investments by the customer or structural changes to existing information systems;

(12) cyber threat — any circumstance, situation or action or inaction, including unauthorised access to, destruction, disclosure, alteration of information or denial of service, that may damage, disrupt, compromise the uninterrupted operation of critical information infrastructure or an information system, or otherwise adversely affect their uninterrupted operation or their users or other persons;

(13) cyberattack — a set of actions carried out intentionally or externally directed with the aim of disrupting the operation of a critical information infrastructure or an information system, obtaining unauthorised access to data processed therein, or adversely affecting data integrity;

(14) cyber incident — any action or interference occurring within a critical information infrastructure, an information system that inevitably compromises or adversely affects the cybersecurity of the critical information infrastructure or the information system, as well as their continuous, uninterrupted and secure operation;

(15) National Computer Emergency Response Team (CERT) — a group of experts of the Autonomous body responsible for the management, coordination, analysis, prevention, response to, resolution, and remediation of the consequences of cyber incidents;

(16) Cybersecurity Operations Centre (SOC) — a centralised cybersecurity monitoring and response unit that monitors information systems on a 24/7 basis, detects threats, and implements security measures;

(17) other regulatory and supervisory body — a body regulating (appointing, qualifying or otherwise issuing permits to operate, licensing) the field of activity of a service provider, exercising supervision and oversight in the cases and as prescribed by law;

(18) cybersecurity service provider — a legal entity, an individual entrepreneur or a natural person engaged under an employment contract who provide cybersecurity services, and in cases provided for by this law — state bodies;

(19) computer — a device that stores, transmits, and processes digital data based on software or a sequence of instructions, and any other equipment used in conjunction with such device for the storage, transmission, or communication of digital data;

(20) risk — the probability of loss or disruption resulting from a cyber incident, expressed as a combination of the magnitude of such loss or disruption and the probability of the occurrence of a cyber incident;

(21) vulnerability — a weakness or flaw in an information system or critical information infrastructure that entails a cyber threat;

(22) cybersecurity specialist — a person appointed by a service provider to bear responsibility for ensuring compliance with cybersecurity requirements applicable to an information system or a critical information infrastructure;

(23) cyber hygiene — a set of cybersecurity measures aimed at maintaining and improving the security and integrity of data within the critical information infrastructure and information system;

(24) information system — an electronic communication network, any device or a group of interconnected or related (connectable) devices or a combination of technical and software and hardware tools operating in vital sectors, one or more of which together perform automatic processing of digital data, or digital data stored, processed, acquired or transmitted by such means specified in this point for the purpose of their use, protection and maintenance.

 

Article 4.

Principles of ensuring cybersecurity

1. Cybersecurity shall be ensured by the following principles:

(1) principle of individuality — ensuring the cybersecurity of an information system or a critical information infrastructure shall be organised by the service provider operating it;

(2) principle of comprehensive protection — the service provider shall assess the potential risks of the information system or the critical information infrastructure it operates, compile a risk assessment scale, determine the severity of the consequences of a potential cyber incident, the scale of impact, the amount of financial resources required to ensure the uninterrupted operation of the information system or critical information infrastructure or to remediate the consequences thereof, and develop a plan of measures for prevention of cyber incidents;

(3) principle of minimising negative impact — in the event of a cyber incident, the service provider shall take appropriate steps and measures prescribed by this Law and the internal regulations for ensuring cybersecurity to prevent the rapid escalation of the cyber incident (expansion of the scale of the impact) and its possible propagation to other systems;

(4) principle of least privilege — the service provider shall ensure that any person or automated process has such a level of access to the information system or critical information infrastructure or the data stored therein that is no more than required to properly perform their job duties or functions;

(5) principle of data confidentiality — only those posessing relevant access permit shall have access to data;

(6) principle of cooperation — while ensuring cybersecurity, preventing and disrupting cyberattacks, cyber threats, as well as resolving cyber incidents, eliminating or mitigating their consequences, the service providers must ensure adequate cooperation with competent state bodies and the public, as well as between each other, also taking into account the interconnection and interoperability between information systems or critical information infrastructures;

(7) principle of integrity — service providers shall protect information against unauthorised alteration or destruction, ensuring its integrity, authenticity, reliability, and accuracy;

(8) principle of availability — service providers shall ensure the timely and proper availability and use of information by competent persons.

 

CHAPTER 2

 

STATE ADMINISTRATION AND REGULATION OF THE FIELD OF CYBERSECURITY

 

Article 5.

Bodies exercising statutory powers in the field of cybersecurity

1. The statutory powers in the field of cybersecurity shall be exercised by the Authorised body, the Autonomous body, and a competent body coordinating the implementation of information security activities.

 

Article 6.

Functions of the Authorised body

1. The functions of the Authorised body shall include:

(1) developing a unified cybersecurity policy and related sector-specific regulatory legal framework, including a strategy or an action plan for ensuring cybersecurity;

(2) developing and implementing awareness-raising and educational events aimed at enhancing the cybermaturity of society;

(3) implementing international commitments in the field of cybersecurity assumed under international treaties of the Republic of Armenia;

(4) conducting professional analysis of cybersecurity indicators reflected in international rating reports, ensuring progress;

(5) in cooperation with the Autonomous body, developing national cybersecurity standards, based on international standards and submitting them to the National Body for Standardisation and Metrology for approval;

(6) developing a list of applicable international standards and submitting it to the Government for approval;

(7) undertaking measures to ensure cybersecurity within information systems and critical information infrastructures during emergency situations, a state of emergency or martial law and throughout the duration thereof, and ensuring supervision over the implementation of such measures;

(8) developing a draft Government decision on establishing the list of critical information infrastructures identified in vital sectors, the service providers operating them and the state bodies responsible for ensuring and supervising compliance with cybersecurity requirements and submitting it to the Government for approval;

(9) developing a draft Government decision on establishing the types of services in vital sectors according to the classifiers of types of economic activity and submitting it to the Government for approval;

(10) developing a procedure defining cases when a legal entity or an individual entrepreneur not deemed a service provider voluntarily assumes and waives cybersecurity ensuring obligations arising from this Law, and submitting it to the Government for approval;

(11) developing a draft Government decision on establishing the criteria for identifying critical information infrastructures operated in vital sectors, and submitting it to the Government for approval;

(12) exercising other powers prescribed by law.

 

Article 7.

Functions of the Autonomous body in the field of cybersecurity

1. The Autonomous body, as a single focal point, shall regulate, manage and oversee activities aimed at registering, preventing, resolving and remediating the consequences of cyber incidents, and shall conduct monitoring and supervision over compliance with the requirements of this Law and legal acts adopted on the basis thereof.

2. The Autonomous body shall perform the following functions:

(1) respond to cyber incidents within the framework of the functions prescribed by this Law;

(2) define and classify the cyber incident response priorities;

(3) register cyber incidents, maintain the cyber incident registry;

(4) analyse cyber incidents;

(5) organise cyber incident prevention measures;

(6) deliver methodological support for risk assessment to service providers;

(7) maintain statistical reporting in the field of cybersecurity;

(8) raise awareness among various groups of society regarding cybersecurity issues (including those aimed at maintaining cyberhygiene), develop and implement awareness-raising and educational programmes in cooperation with the Authorised body and state bodies responsible for education, as well as with legal entities, and provide advisory support to state bodies conducting awareness-raising on cybersecurity issues;

(9) develop and approve minimum requirements for ensuring cybersecurity applicable to information systems operated by service providers (including with respect to information technologies, services, processes and products used, taking into account the specifics of the sectors, sub-sectors or types of services listed in part 4 of Article 16 of this Law) and to critical information infrastructures;

(10) develop and approve the procedure for notification and reporting of cyber incidents by service providers;

(11) develop and approve the standards for cybersecurity audit reports, the procedure for qualification of cybersecurity auditors, and the requirements to persons conducting cybersecurity audits;

(12) develop, approve and implement annual cyberexercise programmes;

(13) organise measures envisaged under the annual cyberexercise programme in state bodies operating information systems or critical information infrastructures;

(14) provide awareness-raising to prevent potential cyber incidents or reduce the impact thereof;

(15) develop and approve guidelines relating to compliance with the requirements prescribed by this Law and the secondary regulatory legal acts adopted on the basis thereof;

(16) conduct monitoring of compliance of service providers with the requirements prescribed by this Law through the procedure prescribed by this Law, elaborate and approve the procedure for monitoring in the field of cybersecurity;

(17) within the scope of its competencies prescribed by this Law, cooperate — with or without the conclusion of bilateral cooperation agreements — with other state bodies, including the authorised state body for national security, authorised bodies for personal data protection and the fight against cybercrimes, as well as bodies responsible for ensuring cybersecurity in foreign countries or relevant Computer Emergency Response Teams. It shall beforehand coordinate with the Authorised body provided for by this Law and, in cases provided for by law, with other authorised bodies the bilateral agreements, memoranda, and other non-legally binding international instruments concluded with bodies responsible for ensuring cybersecurity in foreign countries, international organisations;

(18) report to the law-enforcement bodies, where in the course of its activities, it has suspicion or where sufficient grounds for suspicion arise on the criminal nature of a cyber incident;

(19) exercise supervision over service providers, through the procedure and in the cases prescribed by law, assist the supervision carried out by other regulatory and supervisory bodies established by law, including by filing a motion for imposing liability, the examination of which and adoption of a decision based thereon shall be mandatory;

(20) establish and manage the National Cybersecurity Monitoring Operations Centre;

(21) submit recommendations to the Authorised body concerning amendments or supplements to the list of critical information infrastructures approved by the Government decision;

(22) provide expert support to the Government on cybersecurity-related issues;

(23) develop and approve the procedure for notifying the recipients by the Autonomous body for the purpose of preventing cyber incidents or reducing their impact;

(24) develop and approve the procedure for maintaining Cyber Incident Registry by the Autonomous body;

(25) develop and approve the procedure for maintaining the Register of Service Providers by the Autonomous body;

(26) develop and approve the procedure for collecting and storing information on cyber incidents;

(27) develop and approve the requirements for internal regulations for ensuring cybersecurity by service providers, as well as criteria for assessing risks and cyber incidents;

(28) provide Cybersecurity Operations Centre (SOC) services in state bodies and local self-government bodies;

(29) form working groups and committees in order to exercise the powers provided for by law, and establish an inter-agency commission for the purpose of identifying critical information infrastructures prescribed by part 1 of Article 16 of this Law;

(30) identify critical information infrastructures based on the criteria for identification of critical information infrastructures provided for by part 1 of Article 16 of this Law, preliminarily develop a list of identified critical information infrastructures according to the service providers operating them, and submit such list to the Authorised body;

(31) in accordance with part 5 of Article 16 of this Law, preliminarily develop a list of types of services in vital sectors according to the classifiers of types of economic activity and submit it to the Authorised body;

(32) exercise other powers provided for by law.

3. The Autonomous body shall have the right, in accordance with approved procedures, to transmit information exclusively relating to the prevention and resolution of a cyber incident to the bodies responsible for ensuring cybersecurity of a foreign state or to the relevant computer emergency response teams or international organisations, for performance of the functions provided for by this Law, if the transmission of such information does not harm national security, the legitimate interests of the Republic of Armenia or criminal proceedings. In case the information to be transmitted in accordance with this part relates in any way to the field of defence, national security or foreign relations, the transmission of information shall be beforehand agreed in writing with the authorised bodies for defence, foreign relations, as well as the authorised state body responsible for national security, whereas the transmission of information relating to criminal proceedings shall be agreed in advance with the body conducting the criminal proceedings. In case the information transmitted in accordance with this part constitutes personal data, the transmission of information shall be carried out exclusively in accordance with international treaties.

4. The Autonomous body shall maintain the Register of Service Providers. As necessary, but not less than once every two years, the Autonomous body shall review and update the data contained in the Register of Service Providers approved by it.

5. The bodies developing and implementing state policy in the sectors listed in part 4 of Article 16 of this Law shall, within the scope of their competences, provide information and advisory support to the Autonomous body for the maintenance of the Register of Service Providers specified in part 4 of this Article.

6. The Autonomous body shall ensure the cybersecurity of service providers acting as state bodies and local self-government bodies through the procedure and in the cases established by the Government decision.

7. The scope of Cybersecurity Operations Centre services implemented in state bodies and local self-government bodies shall be defined by the Autonomous body.

8. The Autonomous body shall, in accordance with the procedure established by the Government for the creation of an information technology assets registry and the introduction of a management system, provide inventory management tools to the bodies and organisations specified therein, conduct an audit of the information technology registry, as well as perform methodological analysis.

 

Article 8.

Measures for ensuring cybersecurity of information systems and critical information infrastructures during emergency situations, a state of emergency or martial law

1. During emergency situations, a state of emergency or martial law, and throughout the duration thereof, the Authorised body shall be the state body responsible for taking measures to ensure the cybersecurity of information systems and critical information infrastructures and for exercising supervision over the implementation of such measures, in cooperation with the Autonomous body and the authorised state body for national security.

2. The procedure for taking and overseeing measures to ensure the cybersecurity of information systems and critical information infrastructures during emergency situations, a state of emergency or martial law, as well as the procedure for cooperation with the Autonomous body and the authorised state body for national security, shall be approved by the Government.

 

CHAPTER 3

 

RULES FOR ENSURING CYBERSECURITY

 

Article 9.

Obligations of the service provider

1. The service provider shall, on a continuous basis (seven days a week, twenty-four hours a day), be obliged to take organisational and technical measures in order to:

(1) detect and manage cyber threats;

(2) prevent, detect, block, and resolve a cyber incident;

(3) manage risks to ensure the uninterrupted operation of information systems and critical information infrastructures, to minimise the consequences of a cyber incident, or to prevent and mitigate other derivative or potential impacts.

2. To ensure cybersecurity, the service provider shall be obliged to have an internal regulation for ensuring cybersecurity, setting out the policy adopted by the service provider in the field of cybersecurity, as well as detailing the description of how the service provider complies with the requirements prescribed by this Law and secondary regulatory legal acts adopted on the basis thereof.

3. A service provider shall:

(1) conduct risk assessment of an information system or a critical information infrastructure, compile a risk assessment scale, determine the severity of the consequences of a potential cyber incident and the scale of its impact, approve a plan of measures for prevention of cyber incidents, based on the criteria for assessment of risks and cyber incidents and on the requirements for the internal regulations for ensuring cybersecurity, approved by the Autonomous body;

(2) take organisational and technical measures for risk management, including measures to ensure the physical security of information systems and to prevent unauthorised physical access to, damage to, or interference with computers or other equipment processing, storing, or transmitting information;

(3) ensure documentation of assessed cyber threats to the information system or critical information infrastructure, description of application of security rules and measures;

(4) ensure daily monitoring, in accordance with the requirements prescribed by the internal regulations for ensuring cybersecurity, in order to detect cyberattacks, cyber threats, and vulnerabilities targeting an information system or critical information infrastructure (including the applied information technologies, services, processes, and products the damage or disruption of which compromises the security of the information system and the critical information infrastructure);

(5) notify the Autonomous body, as well as persons potentially affected by the cyber incident, on cyber incidents through the procedure and in the cases prescribed by Article 11 of this Law;

(6) take measures to mitigate the consequences of a cyber incident, prevent its rapid escalation (expansion of the scale of its impact), where necessary, setting full or partial restriction on the operation, accessibility, and access to the information system or the critical information infrastructure;

(7) supervise the processes undertaken to respond to, resolve, and mitigate the consequences of a cyber incident, assess their sufficient and adequate application to the severity and scale of the consequences of the cyber incident, document the results and prepare reports that are subject to retention for a period of no less than three years;

(8) collect information on cyber incidents and retain it for a period of no less than three years from the moment of its creation;

(9) organise general and specialised training courses on cybersecurity for its staff, conduct cyberexercises in cooperation with the Authorised and Autonomous bodies, and ensure its participation in training courses and other capacity-building activities in the field of cybersecurity organised by the Autonomous body;

(10) report, in accordance with the procedure prescribed by law, to the law-enforcement bodies where elements of crime emerge as a result of or during a cyber incident;

(11) ensure compliance with basic cyberhygiene requirements based on the Zero Trust Principle (“never trust, always verify”), such as software updates, information system access management, staff training, and raising awareness on cyber threats and phishing;

(12) carry out other obligations prescribed by this Law, secondary regulatory legal acts adopted on the basis thereof, as well as by the internal regulations of the service provider;

(13) ensure compliance with the minimum requirements for ensuring cybersecurity.

 

Article 10.

Cybersecurity specialist

 

1. The service provider shall — based on the risk assessment of its information systems, the risk assessment scale and the cybersecurity operational model prescribed by point 1 of part 3 of Article 9 of this Law — be obliged to appoint a cybersecurity specialist or specialists, except for the case where ensuring cybersecurity is fully delegated to a cybersecurity service provider as prescribed by Article 19 of this Law.

2. The procedure for qualification of a cybersecurity specialist and the procedure for recognition of qualification shall be established by the minimum requirements for ensuring cybersecurity approved by the Autonomous body. The Autonomous body shall establish the procedure for recognising qualification granted to a cybersecurity specialist by foreign qualification bodies.

3. The Autonomous body shall qualify a cybersecurity specialist in accordance with the procedure for qualification or recognise qualification through the prescribed procedure.

 

Article 11.

Notification of a cyber incident

1. The service provider shall — irrespective of whether the information system or the critical information infrastructure is operated by the service provider itself or by another person, or is hosted by the service provider or another person — immediately upon becoming aware of a cyber incident, but no later than within 24 hours, notify the Autonomous body of any cyber incident:

(1) that has a significant impact on the continuous and uninterrupted operation or secure functioning of the information system or the critical information infrastructure; or

(2) the significant impact of which on the continuous and uninterrupted operation or secure functioning of the information system or the critical information infrastructure cannot yet be assessed or is not yet apparent at the time, but may reasonably be presumed.

2. A cyber incident shall be deemed to have a significant impact if it meets at least one of the following conditions:

(1) the cyber incident poses a threat to human life and health, defence, national security, international relations, the economy, the environment and public order;

(2) in accordance with point 1 of part 3 of Article 9 of this Law, the severity of the consequences of the cyber incident is considered high under the risk assessment scale;

(3) the internal regulations for ensuring cybersecurity prescribed in part 2 of Article 9 of this Law, or the plan of measures for prevention of cyber incidents, or another document describing the continuity or security of the service or a legal act (if any), provide for immediate implementation of emergency response measures in relation to such cyber incident;

(4) as a result of the cyber incident, it is not possible to restore the continuous, uninterrupted and secure operation of the service provided through the information system or the critical information infrastructure within the maximum permissible period provided for by legislation or concluded contract;

(5) due to the cyber incident, the continuity, uninterrupted operation or secure use of the service of another service provider has been disrupted;

(6) due to the cyber incident, the service provider, another interconnected service provider, or relevant service users have suffered or may suffer significant material or non-material damage;

(7) any other unlawful intrusion or interference which, by virtue of its nature, purpose, source of origin, scale or volume, or the resources and measures required for its prevention, or an adequate combination thereof, compromises the continuous and uninterrupted operation or secure functioning of the information system or the critical information infrastructure.

3. Along with the notification on a cyber incident, the service provider shall, where possible, provide the Autonomous body with information about the probable causes and potential consequences of the cyber incident.

4. Within 72 hours after becoming aware of a cyber incident, the service provider shall submit updated information on the cyber incident to the Autonomous body, including information on the severity and consequences of the cyber incident.

5. The Autonomous body may, at own discretion, request the service provider to submit updated information on the severity of the cyber incident, the measures taken, and the resulting consequences.

6. The obligation provided for by point 1 of part 1 of this Article shall not limit the right of the service provider to notify on cyber incidents that do not have a significant impact on the information system or the critical information infrastructure.

7. The service provider shall be obliged to notify persons potentially affected by the cyber incident immediately after becoming aware thereof or, in case no such opportunity is available, within two days.

8. Where the service provider fails to fulfil the notification obligation within the time limits specified in part 7 of this Article, the Autonomous body may notify persons potentially affected by the cyber incident or the public directly, while also informing the service provider thereof.

9. Within one month after submitting the information indicated in part 4 of this Article, the service provider shall submit a final report to the Autonomous body containing information on the probable causes of the cyber incident, the measures applied for its resolution, the severity, consequences and scope of impact of the cyber incident, the time spent and financial resources expended, and the steps and measures taken for further prevention of similar incidents.

 

Article 12.

Voluntary notification

1. Within the meaning of this Law, persons not deemed service providers (including natural persons) may notify the Autonomous body of a cyber incident, cyberattack, cyber threat, or vulnerability of an information system and a critical information infrastructure.

2. The Autonomous body shall consider the notification provided for by part 1 of this Article under the procedure approved in accordance with point 10 of part 2 of Article 7 of this Law; moreover, the Autonomous body shall be obliged to ensure the confidentiality of the notifying person, except where disclosure of information to the relevant competent authorities is required for the detection, preliminary investigation and prevention of crimes. At the same time, where more than one notification concerning cyber incidents is submitted, the Autonomous body shall consider as priority the notifications that are subject to mandatory submission under this Law.

3. The voluntary notification shall not create any additional obligations for the persons referred to in part 1 of this Article that would not otherwise arise for them had they not submitted a voluntary notification to the Autonomous body, except for obligations related to measures for the detection, preliminary investigation and prevention of crimes.

4. Upon receiving the information referred to in part 1 of this Article, the Autonomous body shall inform the service provider thereof immediately, but no later than within 24 hours.

 

CHAPTER 4

 

ENSURING CYBERSECURITY

 

Article 13.

Detection, prevention and resolution of cyber incidents; National Computer Emergency Response Team

1. The detection, prevention and resolution of cyber incidents in the Republic of Armenia (at the national level), as well as the co-ordination of the actions of service providers for the resolution of cyber incidents, shall be ensured by the Autonomous body through the procedure prescribed by this Law; a National Computer Emergency Response Team shall be established within the Autonomous body.

2. For the purposes of ensuring cybersecurity, priority shall be given to the resolution of the cyber incidents prescribed by parts 1 and 2 of Article 11 of this Law and to the remediation of the consequences thereof.

3. During the detection, prevention and resolution of cyber incidents and the remediation of their consequences, the Autonomous body may also co-operate with the relevant computer emergency response teams of foreign states or international organisations (including for the purpose of supporting the process of ensuring cybersecurity), through the procedure prescribed by the international treaties of the Republic of Armenia and this Law.

4. The Autonomous body may, through the procedure prescribed thereby, upon prior notification thereof, conduct vulnerability assessment and penetration testing in respect of service providers operating critical information infrastructure, aimed at assessing the resilience of the service providers’ information systems or critical information infrastructures against external risks, and inform the relevant service provider about any potential vulnerabilities.

5. In order to ensure cybersecurity, the Autonomous body shall monitor website domains within the Internet Protocol (IP) Addresses of the Armenian Internet and, associated with the country code of Armenia, analyse cyber incidents occurring in information systems or critical information infrastructures, as well as their potential impact on the country’s economy, the environment, and human life and health.

6. In order to prevent and resolve a cyber incident, the Autonomous body shall notify the addressees, indicating the measures necessary to prevent further escalation of the cyber incident or to reduce its impact.

7. In case of a cyber threat that, in the assessment of the Autonomous body, may evolve into a cyber incident with significant impact, the Autonomous body may conduct a joint examination of the cyber incident in respect of the service provider, in cooperation with other regulatory and supervisory body of the relevant service provider and, subject to the consent of the service provider, be granted access to information systems or critical information infrastructures in order to ensure proper detection of and response to the cyber incident.

8. When receiving or transmitting information concerning service providers or cybersecurity service providers, the Autonomous body shall be obliged to protect the commercial secrets of such service providers or cybersecurity service providers, as well as any other legally protected secret (where available).

9. Technical and software safeguards provided for by legislation for the secure storage of data shall be ensured with respect to the data processed, stored and transmitted under this Law. Only the competent authorities or persons authorised in accordance with the procedure prescribed by law may have access to such data.

10. Persons failing to meet the basic requirements for employees of the Information Systems Regulatory Body prescribed by the Law “On information systems regulatory body”, or who are subject to the basic restrictions for employees of the Information Systems Regulatory Body prescribed by the same Law, or who have been declared bankrupt and have outstanding (non-discharged) obligations, may not be members of the National Computer Emergency Response Team (CERT) of the Autonomous body.

 

Article 14.

Operation of an information system or a critical information infrastructure by the Autonomous body, or restriction of access thereto

1. In case of a cyber incident having a significant impact, the Autonomous body shall be entitled to take appropriate measures and to fully or partially restrict the operation of, or access to, the information system or the critical information infrastructure used by the service provider, provided that all of the following conditions are simultaneously met:

(1) the cyber incident compromises or harms the cybersecurity of another information system or critical information infrastructure;

(2) the cybersecurity specialist of the service provider is not able or capable to respond — in a timely manner — to a cyber incident having a significant impact or to eliminate other cyber threats arising as a result of the cyber incident;

(3) based on the reasoned and substantiated conclusion of the Autonomous body, there are no other effective means of countering the cyber incident, preventing its further escalation, or neutralising its adverse effects through less intrusive measures;

(4) measures aimed at countering other cyber threats arising from the cyber incident or eliminating the consequences thereof do not cause disproportionate harm to the service provider.

2. The service provider shall be informed by the Autonomous body of the application of the measure provided for by part 1 of this Article immediately, but no later than within 24 hours.

3. The application of the measure provided for by part 1 of this Article shall be coordinated with other regulatory and supervisory body of the relevant service provider. Where urgent measures are required to mitigate the consequences of a cyber incident having a significant impact or to prevent its rapid escalation (expansion of the scale of its impact), and the Autonomous body assesses that any delay would increase the extent of harm caused to the citizens of the Republic of Armenia or to the State, the Autonomous body shall apply the measure referred to in part 1 of this Article without prior coordination with other regulatory and supervisory body of the relevant service provider. The Autonomous body shall, at the earliest opportunity, but no later than within one day after the occurrence of the cyber incident with a significant impact, inform other regulatory and supervisory body of the relevant service provider of the measure applied in the case specified in this part, providing detailed information on the nature of the cyber incident, the steps taken, the necessity and urgency thereof.

4. A protocol shall be drawn up whenever the measure provided for by part 1 of this Article is applied.

 

Article 15.

Cyber Incident Registry

1. The Cyber Incident Registry shall be a database maintained by the Autonomous body where data describing cyber incidents are entered for the purposes of registering, preventing and resolving such incidents, sending notifications, conducting supervisory and monitoring activities, as well as performing other functions arising from this Law.

2. The data received, analysed and provided within the Cyber Incident Registry shall be classified and assigned a confidentiality level in accordance with the procedure prescribed by law. Access to the Registry shall be restricted, and the data stored therein shall be intended for internal use, unless otherwise provided for by law. Information contained in the Cyber Incident Registry may be used solely for the purposes prescribed by this Law.

3. Employees of the Autonomous body who have access to data received, analysed and provided within the Cyber Incident Registry shall maintain the confidentiality of such data during the performance of their duties and after the termination thereof, and shall bear liability as prescribed by law for the unlawful disclosure of such data or its transmission to third parties.

 

CHAPTER 5

 

SPECIFICS OF ENSURING CYBERSECURITY IN VITAL SECTORS

 

Article 16.

Vital sectors and critical information infrastructures operated therein

1. The criteria for identification of critical information infrastructures operated in vital sectors shall be approved by the Government, and for developing such criteria, the Autonomous body shall take as basis the following circumstances:

(1) the potential impact of a cyber incident on the provision of services in one or more vital sectors (systemic effect);

(2) the duration and severity level of a cyber incident in relation to economic activity, the environment, public order, the normal life activity of the population, international relations, governance continuity, national security or public health;

(3) the number of users;

(4) the estimated financial costs required for the restoration of a critical information infrastructure or for the creation of a new one and its current book value.

2. The list of critical information infrastructures identified in vital sectors, the service providers operating such infrastructures, and the state bodies responsible for ensuring and supervising compliance with cybersecurity requirements shall be approved by the Government.

3. By virtue of law, and without the application of identification criteria, the following shall be considered as critical information infrastructures:

(1) information systems operated for provision of qualified trust services;

(2) information systems operated for provision of top-level domain name registry services;

(3) information systems operated for provision of Domain Name System (DNS) services;

(4) information systems operated by state bodies, communities consolidated through the procedure prescribed by law, and the communities of Yerevan and Gyumri, for provision of services to the public;

(5) information systems operated for provision of electronic communications services or Internet access services, where the legal entities operating them meet the criteria for classification of medium-sized enterprises provided for by the Law “On state support for small and medium entrepreneurship”.

4. Within the meaning of this Law, vital sectors shall be:

(1) the energy sector;

(2) the manufacturing sector (manufacturing of chemicals, food products, weapons and ammunition, medical devices, electrical equipment, computer, electronic and optical equipment);

(3) the transport sector;

(4) the water supply and wastewater disposal sector;

(5) the communications sector, including telecommunications;

(6) the postal services sector;

(7) the financial services sector;

(8) the healthcare sector;

(9) the information technology sector, including digital infrastructures;

(10) the sector of radioactive materials, subsoil use and hazardous waste management;

(11) the space activities sector;

(12) the database management and operation sector;

(13) the sector of ensuring safety in emergency situations;

(14) the state administration sector, including digital infrastructures operated by state bodies.

5. The types of services in vital sectors, according to types, classifiers of economic activity, shall be defined by the Government for the purpose of identifying service providers.

6. Based on the identification criteria referred to in part 1 of this Article, the Autonomous body may temporarily designate individual information systems as critical information infrastructures in a vital sector, notify the service provider thereon, and set out measures to be implemented. The notification shall specify a reasonable time limit for implementation of such measures. The measures defined for the information system temporarily designated as a critical information infrastructure shall be aligned with the objective of reducing the risks identified as a result of the vulnerability assessment.

7. Within four months following the notification referred to in part 6 of this Article, the Autonomous body shall take measures to include the information system temporarily designated as a critical information infrastructure in the list referred to in part 2 of this Article. Where the information system is not included in the list referred to in part 2 of this Article upon expiry of the time limit specified in this part, it shall cease to be considered a critical information infrastructure.

 

Article 17.

Key conditions for ensuring cybersecurity in information system and critical information infrastructures

1. In order to ensure cybersecurity in an information system, compliance with the requirements arising from the regulatory functions provided for by this Law, other laws, legal acts adopted on the basis thereof, and by the Law “On the Information Systems Regulatory Body”, including the minimum requirements for ensuring cybersecurity, shall be mandatory. The other regulatory and supervisory body of the service provider may establish requirements that are more stringent than the minimum requirements for ensuring cybersecurity, taking into account the specifics of the regulated sector. Where such requirements are established, audits, supervision and monitoring provided for by law shall be conducted also based on such requirements.

2. In order to ensure cybersecurity of a critical information infrastructure, in addition to complying with the requirements prescribed by part 1 of this Article, service providers shall be obliged to undergo cybersecurity audits, through the procedure and within the time limits prescribed by this Law, on the basis of an applicable international standard (for example, a standard of the International Organization for Standardization (ISO)) or a national standard. The list of applicable international standards shall be established by the Government.

3. Where the management or operation (host of the system) or interoperability of an information system or a critical information infrastructure is delegated to another person, the service provider shall remain responsible for the measures implemented for ensuring cybersecurity and shall act as the focal point with the Autonomous body.

4. Where ensuring the cybersecurity of an information system or a critical information infrastructure is delegated to a cybersecurity service provider, the service provider shall remain responsible for the measures implemented for ensuring cybersecurity and shall act as the focal point with the Autonomous body.

5. Prior to entering into a relevant delegation agreement, and thereafter, the service provider shall be obliged to:

(1) assess and manage the risks that may affect the confidentiality, accessibility or integrity of data stored in an information system or a critical information infrastructure;

(2) assess and verify that the cybersecurity service provider possesses sufficient knowledge of applicable legislative requirements in the field of cybersecurity, practical experience in application, working knowledge and expertise and that sufficient conditions are in place for its employees to provide services in compliance with the principles set out in Article 4 of this Law.

6. The service provider shall in advance reconcile the delegation of obligation for ensuring cybersecurity of an information system or a critical information infrastructure with the Autonomous body. The procedure for reconciliation of the delegation provided for by this part and the list of information to be submitted shall be approved by the Autonomous body.

 

Article 18.

Specifics of ensuring cybersecurity in critical information infrastructures

1. State administration and regulation of cybersecurity in critical information infrastructures shall be carried out taking into account the list of critical information infrastructures approved by the Government.

2. The service provider shall be obliged to take organisational, technical and software measures arising from this Law to ensure the proper cybersecurity of critical information infrastructure, to cooperate with competent state authorities, and to obtain information and advice regarding measures for protection against cyber incidents, as well as methods for their detection, prevention and remediation of the consequences thereof.

 

CHAPTER 6

 

REQUIREMENTS FOR CYBERSECURITY SERVICE PROVIDER

 

Article 19.

Requirements for cybersecurity service provider

1. Ensuring cybersecurity or a part thereof may be delegated to a cybersecurity service provider possessing a document certifying compliance with the criteria and requirements established by an applicable international standard or a national standard in the field of cybersecurity.

2. Where ensuring cybersecurity is delegated to a cybersecurity service provider registered or operating in other countries, the document certifying compliance with the criteria and requirements established by an international standard or a national standard shall be recognised by the Autonomous body on the basis of international cooperation agreements (treaties) applicable in the Republic of Armenia.

3. Legal entities or individual entrepreneurs providing cybersecurity services shall be obliged to undergo a cybersecurity audit through the procedure prescribed by part 2 of Article 20 of this Law, as a result of which the compliance of the internal regulations of the cybersecurity service provider and their implementation with the requirements of this Law shall be assessed. The audit report shall be submitted to the Autonomous body and the service provider within 15 days upon the receipt thereof.

4. The list of applicable international standards shall be established by the Government.

 

CHAPTER 7

 

CYBERSECURITY AUDIT

 

Article 20.

Cybersecurity audit

1. As a result of the cybersecurity audit, the compliance of the internal regulation of the service provider for ensuring cybersecurity and its implementation with the requirements of this Law shall be assessed.

2. The service provider shall be obliged to undergo a cybersecurity audit once every three years, unless other interval is established by an applicable international standard or a national standard. The audit report shall be submitted to the Autonomous body within one month after the receipt thereof. The list of applicable international standards shall be established by the Government.

3. The Autonomous body, in accordance with the requirements to qualification of cybersecurity auditors, shall qualify natural persons and organisations, and shall conduct record-registration of persons holding internationally recognised auditor qualifications acceptable in the Republic of Armenia and shall publish the list thereof on its official website.

4. Given the specifics of the information system or the critical information infrastructure in operation, the service provider may, upon its decision, undergo a cybersecurity audit earlier than the time limit specified in part 2 of this Article.

5. Where, as a result of the examination, the Autonomous body establishes that the cybersecurity audit of a service provider has not been conducted in compliance with the requirements of this Law or of cybersecurity audits, it may request the service provider to undergo a new cybersecurity audit.

6. The person conducting the cybersecurity audit shall be remunerated by the service provider.

 

CHAPTER 8

 

SUPERVISION, MONITORING AND LIABILITY FOR COMPLIANCE WITH THE REQUIREMENTS OF THE LAW AND LEGAL ACTS ADOPTED ON THE BASIS THEREOF

 

Article 21.

Supervision over compliance with the requirements of the Law and legal acts adopted on the basis thereof

1. The Autonomous body shall exercise supervision over compliance with the requirements of this Law and the legal acts adopted on the basis thereof under the procedure prescribed by the Law “On Information Systems Regulatory Body”.

2. The Autonomous body shall exercise supervision over information systems or critical information infrastructures of vital importance operated by other regulatory and supervisory bodies through monitoring, on the basis of audit results obtained from such bodies under the procedure prescribed by this Law.

 

Article 22.

Monitoring conducted by the Autonomous body

1. The Autonomous body shall, in the cases and through the procedure prescribed by this Law, conduct monitoring of the activities of service providers (hereinafter referred to as “the monitoring”) in order to assess the compliance of measures for ensuring cybersecurity applied in the information systems or the critical information infrastructures of service providers with the requirements prescribed by this Law and by secondary regulatory legal acts adopted on the basis thereof.

2. Monitoring may be conducted both at the Autonomous body and, with consent of the service provider, at its premises, at the location where the service provider is established or performs its activities.

3. When conducting monitoring, computer technologies and other technical or software tools, electronic and other equipment and storage media may be used, and other actions aimed at conducting the monitoring and summarising its results may be performed.

4. The Autonomous body shall conduct monitoring of a service provider in the following ways:

(1) assessment of compliance with the minimum requirements for ensuring cybersecurity;

(2) assessment of compliance with individual measures envisaged by the plan of measures for prevention of cyber incidents prepared based on risk assessment;

(3) assessment of compliance with the requirements set out in the report prepared based on the results of the cybersecurity audit conducted by a qualified auditor;

(4) in other cases provided for by law.

5. Prior to conducting monitoring at the premises of a service provider, the Autonomous body shall inform the service provider and the other regulatory and supervisory body of the relevant service provider thereon, indicating the subject matter, purpose, time period, and location of the monitoring.

6. A protocol shall be drawn up based on the monitoring results, with regard to which the service provider shall have the right to submit objections or recommendations to the Autonomous body, within seven days after the receipt thereof.

7. The Autonomous body may issue binding instructions to the service provider and set timetable for implementation of such instructions or elimination of deficiencies, in coordination with the other regulatory and supervisory body of the relevant service provider. The service provider shall be obliged to follow the instructions issued by the Autonomous body or eliminate the detected deficiencies in accordance with the set timetable and to inform the Autonomous body thereon, providing evidence.

8. No liability measures may apply on the basis of the monitoring results.

 

Article 23.

Consequences of non-compliance with the lawful requests of the Autonomous body

1. Where a service provider or a cybersecurity service provider fails to comply with the lawful requests of the Autonomous body, the Autonomous body shall:

(1) apply to the superior body of the service provider or cybersecurity service provider, or to the relevant official, in order to initiate a procedure for imposing disciplinary liability on the person having failed to fulfil his or her duties;

(2) apply to the other regulatory and supervisory body of the service provider, requesting the initiation of relevant proceedings and the imposition of liability on the service provider;

(3) initiate a process of conducting a conformity assessment through the procedure prescribed by law;

(4) fully or partially restrict the opportunity to use the state information system or the data exchange layer until the lawful requests of the Autonomous body are fulfilled, where it has reasonable grounds to believe that non-imposition of such restriction may disrupt the secure and uninterrupted operation of the state information system.

2. The consequence provided for by point 4 of part 1 of this Article may be applied either independently or simultaneously with those provided for by points 1, 2 or 3.

3. The official entitled to impose disciplinary liability shall, within one month after receiving the application, take measures and inform the Autonomous body on the results.

4. The other regulatory and supervisory body of the service provider shall inform the Autonomous body on the progress of the application for initiating relevant proceedings and imposing liability within 15 days after receiving the application.

 

Article 24.

Liability for violation of the requirements of this Law

1. Violation of the requirements of this Law shall entail administrative or criminal liability prescribed by law.

2. A service provider or a cybersecurity service provider, or their employees (managers), may not be subjected to property or administrative liability for the proper performance of their duties arising from this Law.

3. Public servants or employees of the Autonomous body may not be subjected to property or administrative liability for the proper performance of their duties provided for by this Law.

 

CHAPTER 9

 

FINAL PART AND TRANSITIONAL PROVISIONS

 

Article 25.

Final part and transitional provisions

1. This Law shall enter into force on the tenth day following the day of its official promulgation, except for:

(1) Article 8 of this Law, which shall enter into force from the moment the secondary regulatory legal act prescribed by part 2 of that Article enters into force;

(2) part 2, and points 1, 4, 5 and 13 of part 3 of Article 9 of this Law, which shall enter into force from the moment the relevant secondary regulatory legal acts enter into force.

2. The service providers operating critical information infrastructures and cybersecurity service providers shall, within a twenty-four-month period after the Law enters into force, submit to the Autonomous body a document certifying compliance with the criteria and requirements established by an international standard or a national standard in the field of cybersecurity.

3. The cybersecurity service providers shall undergo a cybersecurity audit one year after obtaining the document certifying compliance with international or national standards in the field of cybersecurity.

4. The secondary regulatory legal acts arising from this Law, including the national standard, shall be adopted within a twelve-month period after this Law enters into force.

5. The service providers shall adopt their internal regulations for ensuring cybersecurity, conduct risk assessments for the information systems or the critical information infrastructures they operate and develop a plan of measures for prevention of cyber incidents within an eighteen-month period after this Law enters into force.

 

President of the Republic

V. Khachaturyan

 

24 December 2025

Yerevan

HO-442-N

 

Date of official promulgation: 25 December 2025.

 

Translation published on a joint site 17 July 2026.